Pod中openssh-server SSH连接失败:Connection reset by <IP> port 30500求助
问题:K8s Pod中部署openssh-server后SSH连接报错Connection reset by port 30500
sshd服务器日志
debug2: load_server_config: filename /etc/ssh/sshd_config debug2: load_server_config: done config len = 806 debug2: parse_server_config: config /etc/ssh/sshd_config len 806 debug3: /etc/ssh/sshd_config:17 setting Port 30500 debug3: /etc/ssh/sshd_config:19 setting ListenAddress 0.0.0.0 debug3: /etc/ssh/sshd_config:22 setting HostKey /etc/ssh/ssh_host_rsa_key debug3: /etc/ssh/sshd_config:23 setting HostKey /etc/ssh/ssh_host_ecdsa_key debug3: /etc/ssh/sshd_config:24 setting HostKey /etc/ssh/ssh_host_ed25519_key debug3: /etc/ssh/sshd_config:36 setting SyslogFacility AUTH debug3: /etc/ssh/sshd_config:38 setting LogLevel VERBOSE debug3: /etc/ssh/sshd_config:43 setting PermitRootLogin yes debug3: /etc/ssh/sshd_config:44 setting StrictModes no debug3: /etc/ssh/sshd_config:52 setting AuthorizedKeysFile .ssh/authorized_keys debug3: /etc/ssh/sshd_config:60 setting HostbasedAuthentication no debug3: /etc/ssh/sshd_config:68 setting PasswordAuthentication no debug3: /etc/ssh/sshd_config:73 setting ChallengeResponseAuthentication no debug3: /etc/ssh/sshd_config:83 setting GSSAPIAuthentication no debug3: /etc/ssh/sshd_config:84 setting GSSAPICleanupCredentials no debug3: /etc/ssh/sshd_config:105 setting X11Forwarding yes debug3: /etc/ssh/sshd_config:131 setting AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES debug3: /etc/ssh/sshd_config:132 setting AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT debug3: /etc/ssh/sshd_config:133 setting AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE debug3: /etc/ssh/sshd_config:134 setting AcceptEnv XMODIFIERS debug3: /etc/ssh/sshd_config:137 setting Subsystem sftp /usr/libexec/openssh/sftp-server debug1: sshd version OpenSSH_7.4, OpenSSL 1.0.2k-fips 26 Jan 2017 debug1: private host key #0: ssh-rsa SHA256:6XsUKJrlEzspiLw1H/e5qfrzga/n4Rgs debug1: private host key #1: ecdsa-sha2-nistp256 SHA256:yJkcJ2AX3E4dOADjCRn9EWnut+z5nW3xKhGOc debug1: private host key #2: ssh-ed25519 SHA256:GHvEepwimuJpanKOXJx8Aacpcs8MwXxlmaU7Q debug1: rexec_argv[0]='/usr/sbin/sshd' debug1: rexec_argv[1]='-ddd' debug3: oom_adjust_setup debug1: Set /proc/self/oom_score_adj from 1000 to -1000 debug2: fd 3 setting O_NONBLOCK debug1: Bind to port 30500 on 0.0.0.0. Bind to port 30500 on 0.0.0.0 failed: Address already in use. Cannot bind any address.
SSH命令日志
ssh -vvv localhost -p 30500 OpenSSH_7.4p1, OpenSSL 1.0.2k-fips 26 Jan 2017 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 58: Applying options for * debug2: resolving "localhost" port 30500 debug2: ssh_connect_direct: needpriv 0 debug1: Connecting to localhost [::1] port 30500. debug1: connect to address ::1 port 30500: Connection refused debug1: Connecting to localhost [127.0.0.1] port 30500. debug1: Connection established. debug1: permanently_set_uid: 0/0 debug1: key_load_public: No such file or directory debug1: identity file /root/.ssh/id_rsa type -1 debug1: key_load_public: No such file or directory debug1: identity file /root/.ssh/id_rsa-cert type -1 debug1: key_load_public: No such file or directory debug1: identity file /root/.ssh/id_dsa type -1 debug1: key_load_public: No such file or directory debug1: identity file /root/.ssh/id_dsa-cert type -1 debug1: key_load_public: No such file or directory debug1: identity file /root/.ssh/id_ecdsa type -1 debug1: key_load_public: No such file or directory debug1: identity file /root/.ssh/id_ecdsa-cert type -1 debug1: key_load_public: No such file or directory debug1: identity file /root/.ssh/id_ed25519 type -1 debug1: key_load_public: No such file or directory debug1: identity file /root/.ssh/id_ed25519-cert type -1 debug1: Enabling compatibility mode for protocol 2.0 debug1: Local version string SSH-2.0-OpenSSH_7.4 debug1: Remote protocol version 2.0, remote software version OpenSSH_7.4 debug1: match: OpenSSH_7.4 pat OpenSSH* compat 0x04000000 debug2: fd 3 setting O_NONBLOCK debug1: Authenticating to localhost:30500 as 'root' debug3: put_host_port: [localhost]:30500 debug3: send packet: type 20 debug1: SSH2_MSG_KEXINIT sent Connection reset by 127.0.0.1 port 30500
服务器运行状态
netstat -anp | grep 30500 tcp 0 0 0.0.0.0:30500 0.0.0.0:* LISTEN 1/sshd
观察结果
- 同一镜像在本地Docker容器中运行正常(临时允许密码认证的相同sshd_config)
- 服务已关联正确端点,可telnet到自定义SSH端口30500
- SSH进程在Pod中正常运行
- 从其他Pod或集群外telnet到SSH端口均正常
- 同一Pod内运行在80端口的nginx容器工作正常
- 当前错误情况:
- NodePort或LoadBalancer(OCI)均无法正常工作
- 从Pod内部、其他Pod或工作节点SSH到localhost均失败
解决建议
1. 修复sshd进程启动异常
sshd启动日志显示端口绑定失败,但netstat显示PID 1的sshd在监听,说明进程可能处于异常状态:
- 进入Pod执行
ps aux,检查是否存在多个sshd进程,确认PID 1的sshd是否正常运行 - 杀死现有sshd进程并重新启动:
用kill 1 && /usr/sbin/sshd -D-D参数让sshd前台运行,适配容器环境,避免后台运行导致的进程管理问题
2. 调整认证配置排除认证失败
SSH客户端日志显示没有可用的密钥文件,同时sshd配置禁用了密码认证(PasswordAuthentication no),这会导致认证失败进而连接被重置:
- 临时修改
/etc/ssh/sshd_config,设置PasswordAuthentication yes,重启sshd后用密码测试连接 - 如果需要密钥认证,确保客户端的公钥已添加到Pod内
/root/.ssh/authorized_keys文件中,且文件权限为600,目录权限为700
3. 确保主机密钥正确生成
容器启动时如果没有预先生成SSH主机密钥,可能导致连接异常:
- 在容器启动脚本中添加生成主机密钥的命令:
确保sshd启动前完成密钥生成ssh-keygen -A
4. 排查端口冲突与容器网络限制
- 检查Pod内是否有其他进程占用30500端口,执行
lsof -i :30500确认(若未安装lsof,用netstat -tulpn) - 检查Kubernetes NetworkPolicy是否限制了SSH流量,确保相关Pod、节点之间的30500端口允许通信
- 临时关闭容器内的SELinux(执行
setenforce 0),测试是否是安全模块限制导致的连接重置
内容的提问来源于stack exchange,提问作者Arpit Jain
相关产品推荐
相关产品推荐

